On Fri, 2005-Nov-18 14:42:44 +1000, Timothy Smith wrote:
>i have seen a similar attack recently doing a brute force ssh. the 
>number ONE weakness in most poorly run IT systems, is easy passwords. 
>it's amazingly easy to brute force these systems using common names or 
>variations of them.

I strongly recommend that you disable reusable passwords on any system
exposed to the Internet - RSA/DSA or OPIE are much harder to brute force.
You can also use AllowUsers to further limit exposure.

-- 
Peter Jeremy
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "[EMAIL PROTECTED]"

Reply via email to